Levels of customer authorization

You use customer authorization settings in the Security Groups (SP) application to set the level of access a security group has to customer–level information.  

You can assign each security group one of five levels of customer authorization. The selected level of authorization applies to all users in the security group. If a user requires more than one type of authorization, create additional security groups and assign the user to each of them. His or her customer-level data restrictions are based on the combination of settings for all of the groups.

You can assign a security group one of the following levels of access:

Access to all customer-level information

You can authorize a security group to access all customer-level information. Users with this level of customer authorization can access information that is associated with any customer and any customer-level information that is not associated with a customer.

For example, Hamed is the director of operations for a service provider. He is responsible for all maintenance activities for all customers of the service provider and requires access to all customer agreements and transactions. As a result, Hamed belongs to a security group that is authorized to access all customer-level information.

Access to customer-level information that is not associated with a customer

You can authorize a security group to access only unrestricted customer-level information. Users with this level of customer authorization can access all information that is not associated with a customer.

For example Best Services owns the fire extinguishers that its customers use, so no customers are associated with those assets. Josh is responsible for checking all of the fire extinguishers on behalf of Best Services. He has no customer responsibilities. Josh is in a security group with access to unrestricted customer-level information only, so that he can view details about the fire extinguishers, but not about any assets that the customers own.

Access to information only about a user’s employer

A security group can allow its users access to customer-level information for the users’ employers only. A user in a group with this level of customer authorization can access customer-level information for one customer; the company in the Customer/Vendor field on his or her person record in the People (SP) application.

Users with this level of customer authorization cannot access unrestricted customer-level information, except for unrestricted (global) classifications and attributes.

For example, Maria works for the International Sailing Association (ISA), a customer of the service provider Best Services. Maria’s person record in the People (SP) application has the value ISA in the Customer/Vendor field, because ISA is her employer. She belongs to a security group that has access to a user’s employer. As a result, she can view all customer-level information for ISA. She cannot view customer-level information for any other customers of Best Services, nor can she view any customer-level information that is not associated with a customer, except for unrestricted classifications and attributes.

The users in this group are typically employees of a service provider's customers, and have limited access to data and applications. For example, these users typically can access only the self service and bill review applications.

Access to information only about a user’s assigned customers

A security group can be authorized so that its users can access all of their assigned customers. A user in a group with this level of customer authorization can access customer-level information for all of the customers that are listed on the Customer Access List in the People (SP) application.

Users can also access all information that is not associated with a customer.

For example, Edouard is a customer service agent who is assigned to support Acme Products and Alpha Industries. The customer access list on the person record for Edouard lists these two customers, and he belongs to a security group with access to any customer on the user’s customer access list. As a result, Edouard can view all customer-level information for these two companies.

Because a co-worker is absent, Edouard must also handle calls from the XYZ Corporation for today. Regina is the service desk manager and has access to XYZ corporation, in addition to Acme Products and Alpha Industries. Instead of changing Edouard’ security profile, Regina uses the People (SP) application to add XYZ Corporation to Edouard’s customer access list. Edouard can now work with Acme Products, Alpha Industries, and XYZ Corporation for the duration of his shift. Regina can remove XYZ Corporation from Edouard’s customer access list at the end of his shift.

Access to information about specific customers

You can authorize a security group can so that its users can access information about specific customers. A user in a group with this level of customer authorization can access all customer-level information for all of the customers that are listed in the Individual Customer Authorization list for the security group.

Users can also access all information that is not associated with a customer.

For example, Elena and Max are service desk agents who work for a service provider. Elena has responsibility for Acme Products and General Manufacturing. Max has responsibility for Alpha Industries and XYZ Corporation. If either Elena or Max is away, the other takes on responsibility for his or her customers. Elena and Max belong to a security group that gives them access to the customers listed in the Individual Customer Authorization list. Acme Products, General Manufacturing, Alpha Industries, and XYZ Corporation are all in the list for the security group so that both Elena and Max, and any other service desk agents in the same security group, can access all four customers as necessary.

See Also

Customer-level data restrictions and customer authorization

Assigning levels of customer authorization to security groups